Transcript
A (0:00)
Foreign. Hey everyone, I'm James Wilson from Risky Business. Joining me for this sponsored interview is David Gettman from corelight. Corelite makes incredible NDR hardware that runs at phenomenal line rate speeds. I'm talking up to 200 gigabits per second. It's a hardware platform that runs a highly optimized version of the open source Zeek monitoring tool. Essentially, it's on your network collecting everything all the time because if it happened, it's visible on the network. In this interview, David talks about the new corelight agentic triage features that they've added to help customers make sense of this incredible amount of data that corelight can capture. So I'll drop you here into the chat where David answers my cheeky challenge of whether this is just another AI inside badge being slapped on an existing product or. Or in fact, as it turns out, there is a whole lot more to this. Enjoy.
B (0:58)
It's not following the crowd. We are very much customer focused and everything we do is really for customer outcomes. One of the reasons is because we are increasingly seeing interest in buyers coming to us who are smaller and smaller teams. And so in other words, NDR and the network evidence is becoming more and more important for small teams. And having agents that make that learning curve of network evidence that isn't always there in a small team, as well as the automation and the efficiency that comes from agents, is something that those customers really need and, and is already making a very big, powerful difference for them. And the second is that it is impossible. I don't think anyone knows for sure the exact future of AI, but if you look at recent kind of headlines like the leak from Anthropic with the Mythos and Capybara models coming, where they're holding them back because they're worried about the power, because Anthropic has been used, or Claude has been used so several times now, where attackers have been able to break through the guardrails and use it for malicious attacks. And they're worried about the capabilities that these models are going to allow attackers who manage to get past the guardrails to have. And they've used the word specifically that they're worried about overwhelming defenders. And so this is where what we were worried about a year ago and we really believed that that AI attacks were going to require an AI defense. And so that's the difference between having a true agentic system that's built on agentic technologies versus not having a more legacy kind of codified system. And so having something that can reason and think in the midst of a sophisticated, somewhat novel attack that's coming from a really advanced AI, we think is going to become a incredible amount of value out of just pure necessity in the very near future. Things are moving very quickly, Right?
A (3:22)
Yeah. And I think that line there is so important, right, that these models, I think, already do overwhelm defenders. And if the antics we've seen from Team PCP and the sheer amount of just wreckage and credential theft that came out of that is any indication, if that's what they can do with today's model and Anthropic is squared about what the capabilities are of the models they haven't released yet, then yeah, it's a scary time to be a defender. But it's also not enough to just have an agent to help you out with this. Right? And I think, if I'm understanding correctly, sort of the premise here, it's you guys bring the combination of you've got agentic for a reason, for a purpose, combined with the fact that you've got the full set of everything that's happened, right? If it's happened, it's on the network and so you've got all that data. So is that the winning combination that you guys can facilitate here?
